Cross-Origin Scripting Engine for Secure Application Collaboration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing access to network resources and monitoring for potential misuse across diverse client devices and network applications from different origins is challenging due to differences in access methods and security policies, limiting collaboration and integration between applications from different entities and servers.

Innovation Solution

A client application executes an application script within an embedded browser, establishing a domain of trust to enable cross-application collaboration by overriding same-origin policies, allowing data transfer and policy implementation across network applications from different entities and origins, using a scripting engine to generate scripts that meet security policies of various applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If same-origin policies are enforced to maintain security, then security is improved, but collaboration and integration between network applications from different origins deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidcollaboration between applications
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary component (the client application with scripting engine) that mediates between network applications from different origins. This intermediary establishes a domain of trust and executes application scripts that enable cross-origin collaboration while maintaining security boundaries, thus resolving the contradiction between security enforcement and application interoperability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If access methods are standardized across client devices, then ease of management is improved, but adaptability to different client devices and access conditions deteriorates

Engineering Contradiction:
Improveaccess managementVSAvoiddevice compatibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal access method where the client application with embedded browser and scripting engine can operate across diverse client devices (mobile phones, tablets, laptops, desktops) with different operating systems and browsers. The application scripts provide multi-functional capabilities to handle various access conditions and device types uniformly, thus achieving both ease of management and device adaptability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3850816B1Application scripts for cross-domain applications
Publication Date: 2024.06.05 CITRIX SYSTEMS INC
  • EP3850816B1 patent drawingFigure 1
  • EP3850816B1 patent drawingFigure 2
  • EP3850816B1 patent drawingFigure 3

AI summary

Embodiments described include systems and methods for executing in an embedded browser an application script for network applications of different origins. A client application can establish a first session with a first network application of a first entity at a first origin via an embedded browser within the client application and a second session with a second network application of a second entity at a second origin via the embedded browser within the client application. A scripting engine within the client application of a client device of a user at a third origin can identify an application script having instructions to interact with the first network application and the second network application, and can execute the instructions to perform a task across the first network application of the first entity at the first origin and the second network application of the second entity at the second origin.